# Issues with dates/times that don't have a timezone (Logstash/Kibana)

**URL:** <https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008>\
**Category:** Logstash\
**Created:** [November 14, 2016, 4:07pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008 "2016-11-14T16:07:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![s33butler](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@s33butler](https://discuss.elastic.co/u/s33butler)\
**Post date:** [November 14, 2016, 4:07pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/1 "2016-11-14T16:07:59Z")

</div>

The basic issue is when I try and replace @timestamp with another date setting the timezone option all other dates are 5 hours off in Kibana because they are stored without a timezone and Kibana assumes they must be UTC.

More detail using sample data...

csv columns =\> ["receive\_time","generated\_time","start\_time"]  
line would look like ( dates in EST / UTC -5 / -0500) = 2016/11/07 13:09:44,2016/11/07 13:09:39,2016/11/07 13:09:40

Since they are firewall syslog entries, I would prefer that @timestamp use "generated\_time" for auditing purposes incase there is an issue with syslog and/or older logs need to be imported.

```
date {
  locale => "en"
  timezone => "America/New_York"
  match => ["generated_time", "yyyy/MM/dd HH:mm:ss"]
  tag_on_failure => ["_dateparsefailure"]
}

```

Here is where it breaks down...  
The timestamp is converted to ISO8601(UTC) using the new date (2016/11/07 13:09:39) ...  
"@timestamp" =\> "2016-11-07T18:09:39.000Z",

The other three dates are left as is...  
"receive\_time" =\> "2016/11/07 13:09:44",  
"generated\_time" =\> "2016/11/07 13:09:39",  
"start\_time" =\> "2016/11/07 13:09:40",

Because Kibana setting use the Browsers timezone offset (EST / UTC -5 in my case) all the other times are assumed UTC and then lose 5 hours.  
2016/11/07 13:09:44 \>\> 2016/11/07 08:09:44

I have read so many posts now I don't know what the best solution is. I imagine if I can just add the -0500 timezone to my times then all should be good?

Do I do that at CSV, Mutate, or Date?  
date {  
timezone =\> "America/New\_York"  
match =\> ["generated\_time\_orig", "yyyy/MM/dd HH:mm:ss"]  
target =\> "generated\_time\_fixed"  
}

or

mutate {  
replace =\> ["generated\_time", "%{generated\_time}-05:00"]  
}

Not even sure if I have the mutate one right and I assume I have to have a "date" target for each time I want to fix.

Any assistance would be greatly appreciated,  
Scott

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 14, 2016, 4:20pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/2 "2016-11-14T16:20:38Z")

</div>

If I understand you correctly it sounds like the issue is that some of the times are run through the date filter, using the `timezone` property to correct the offset. Have you tried running all time fields through the date filter? You can use the `target` setting in the date filter to have the date filter overwrite the `start_time` field, for instance, with the output of the date filter.

---

<div class="post-metadata">

**Author:** ![s33butler](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@s33butler](https://discuss.elastic.co/u/s33butler)\
**Post date:** [November 14, 2016, 4:27pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/3 "2016-11-14T16:27:15Z")

</div>

You are understanding correctly, I am asking where the best place to fix each time's timezone is.

If I use the date filter, do I have to setup a separate one for each time to be fixed or can I do multiple matches/targets in one date filter? Also, you are saying I can just overwrite "start\_time" I don't have to do a "start\_time\_orig" =\> "start\_time\_fixed"?

Thanks for your time and assistance,  
Scott

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 14, 2016, 4:31pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/4 "2016-11-14T16:31:01Z")

</div>

Unfortunately no, we do not support that. You'll to use a date filter per field. That would be a welcome patch however!

You'll need to do something like:

```auto
date {
  timezone => "..."
  match => ["myfield"]
  target => ["myfield"]
}

```

For each field.

---

<div class="post-metadata">

**Author:** ![s33butler](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@s33butler](https://discuss.elastic.co/u/s33butler)\
**Post date:** [November 14, 2016, 5:44pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/5 "2016-11-14T17:44:37Z")

</div>

Oh man, that might be a bunch of date filters for some of my logs. I would have thought appending the timezone using the mutate filter might be more efficient.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![andrewvc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewvc/32/5064_2.png) [@andrewvc](https://discuss.elastic.co/u/andrewvc)\
**Post date:** [November 14, 2016, 7:59pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/6 "2016-11-14T19:59:04Z")

</div>

@s33butler I think your use case makes sense. Can you open an issue on [http://github.com/logstash-plugins/logstash-filter-date](http://github.com/logstash-plugins/logstash-filter-date) ? I think we should have a better way of handling your use case.

---

<div class="post-metadata">

**Author:** ![s33butler](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@s33butler](https://discuss.elastic.co/u/s33butler)\
**Post date:** [November 14, 2016, 8:15pm UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/7 "2016-11-14T20:15:48Z")

</div>

Oh gosh, I'll see what I can do. Figure someone ran into this before, and was looking how best to tackle it. I didn't want to bring it up, but it gets real messy if you have syslogs from different timezones. Say I have firewalls in both UTC -5 and UTC -8, now I need 12 date filters as it is basically 6 x timezones for my scenario.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 22, 2016, 12:21am UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/8 "2016-11-22T00:21:11Z")

</div>

@s33butler this usually isn't an issue because usually people have timestamps with an included zone, or they don't have quite so many timestamps.

This could be a good place to use the `ruby` filter to judiciously convert dates to [ISO8601 with zone](https://en.wikipedia.org/wiki/ISO_8601#Time_offsets_from_UTC).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2016, 12:21am UTC](https://discuss.elastic.co/t/issues-with-dates-times-that-dont-have-a-timezone-logstash-kibana/66008/9 "2016-12-20T00:21:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
